Consumer Health Data Privacy Policy

Last Updated: September 18, 2026

Version 3.0

This Consumer Health Data Privacy Policy applies to consumer health data that Bazu Technologies, LLC (“Bazu,” “we,” “us”) collects about residents of Washington under the My Health My Data Act (RCW 19.373) (“MHMDA”) and residents of Nevada under Senate Bill 370 (NRS Chapter 603A). It is published as a separate, distinctly linked document as required by Washington law. Section 13 says how it applies in other states with a health-data law.

Bazu does not measure your body. Even so, what you log about food, how you say a meal left you, and your weight are consumer health data under these laws, because the laws cover diet, bodily functions and inferences drawn from them. This policy is about that data.

This is version 3.0. It applies to app version 2.3.0 and later. This policy applies only to consumer health data. For all other personal information we collect, see our Privacy Policy and our Terms of Service.

1. What "Consumer Health Data" Means

“Consumer health data” is personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status (RCW 19.373.010; NRS 603A). In Bazu's case the covered categories are:

  • Diet: the food you log
  • Bodily functions and symptoms: how you say a meal left you
  • Measures of health status: your height, weight and weight goal
  • Health conditions: a diabetes answer an earlier app version stored
  • Inferences drawn from any of the above: the reads and scores Bazu works out from your food

2. Categories of Consumer Health Data We Collect

The categories of consumer health data we collect from or about you are:

  • Meals you log: descriptions, photos, barcodes, foods you search for, ratings and notes, with the time you logged each one
  • Your energy check-in answer: how a meal left you, in your own words or on a scale. It is your own report, stored with that meal, and it never enters any score
  • Estimated nutrition values for each meal (macronutrients, calories, sugar, fiber and similar values)
  • The reads and scores we infer from your meals: each food's Nutrition Score, Energy read and Ingredients check, and your Bazu Score, a single number for the last 30 days
  • Height and weight, and a dated history of every weight you log
  • Weight goal and how fast you want to reach it; wellness goals; nutrition goals (e.g., cut added sugar, more protein, more fiber)
  • Self-reported diabetes status. App versions before 2.3.0 asked one question during onboarding: none, pre-diabetes, Type 2 diabetes, Type 1 diabetes, other, or not sure. App version 2.3.0 and later does not ask. In September 2026 we changed every stored pre-diabetes and Type 2 answer to none. App versions before 2.3.0 can still send those answers, so an account may hold one again. We keep a dated record of what was first reported, and we never rewrite it. We still read the stored answer, for the purpose described in Section 4

Categories app versions before 2.3.0 collected:

  • Blood glucose readings and insulin doses entered by hand. App version 2.3.0 and later has no screen for either one. Values entered earlier are still held on your account while it is active
  • Continuous glucose monitor (CGM) readings imported from Apple Health, if you enabled that integration, and the curves and time-in-range statistics computed from them. The integration was removed in app version 2.3.0 and every imported reading and derived figure was deleted from every account fourteen days after that version was released (Section 10)

Hand-entered values are listed because holding data is collecting it under Washington law. Our only purpose for them is storage, export on request and deletion.

3. Sources of Consumer Health Data

We collect consumer health data from the following sources:

  • Directly from you, when you complete onboarding, log a meal, take a meal photo, answer an energy check-in, log a weight, or use any feature of the Service.
  • Inferred by Bazu about you: the reads and scores in Section 2 are worked out from the food you log and stored alongside your account. They describe the food, and the same food gets the same reads for every account.
  • Apple Health, with your permission, in app versions before 2.3.0 (removed): those app versions could read blood glucose samples from Apple Health if you enabled CGM integration. Apple Health glucose import was removed in app version 2.3.0. App version 2.3.0 and later does not request Apple Health permission and imports nothing from it. An app version before 2.3.0 still installed on a device may keep syncing until that device updates; readings received that way are deleted on the next run of the same deletion (Section 10). If you granted permission to an earlier app version, you can review or revoke it in iOS Settings → Health → Data Access & Devices → Bazu.

4. Purposes for Which We Collect, Use, and Share Consumer Health Data

We collect, use, and share consumer health data only for the following purposes:

  • To provide and operate the Service you requested: displaying your meals, working out the three reads and your Bazu Score, suggesting a fix to a meal, and personalizing the Service to your goals
  • To show your energy check-in answers back to you beside each meal and in your history. We do not use them to compute any score
  • To process meal descriptions and meal photos through OpenAI, for the limited purpose of identifying foods and estimating nutrition
  • To send Anthropic a summary of your recent logging, so it can write the sentences on your score screens (Section 5 lists what that summary carries)
  • To hold the predicted glucose curve back from accounts that reported Type 1 diabetes. App versions before 2.3.0 drew that curve. Our servers check the stored answer on every request. App version 2.3.0 and later draws no curve for anyone
  • To store, export on request and delete the hand-entered values app versions before 2.3.0 collected (Section 10)
  • To keep the Service secure and to diagnose technical issues
  • To respond to your support requests and to communicate with you about your account
  • To comply with applicable law and respond to lawful legal requests

In app versions before 2.3.0 we also used blood glucose readings imported from Apple Health to show glucose trends in the app and to overlay your own readings on the Estimated Glucose Curve. That use ended in app version 2.3.0. We have never sent CGM readings to any AI model or AI vendor. We have never used them to train a model, and we never will.

We do not collect, use, or share consumer health data for any purpose not listed above. We will not use consumer health data we already hold for a new purpose without first telling you and asking for your consent again. We do not engage in geofencing within or around any healthcare facility, including within 1,750 feet of one.

5. Categories of Consumer Health Data We Share, and With Whom

We share consumer health data only with a limited set of service providers who help us operate the Service. Each one is a processor: it acts on our written instructions under a contract, uses the data only for the purpose we name, and may not use it for anything of its own. Under RCW 19.373.010 a disclosure to a processor is not a “share,” so we do not ask for a separate sharing consent. The list is complete.

  • Supabase (cloud database, storage, and authentication, U.S.-based): receives all of the categories listed in Section 2 in order to store them on your behalf.
  • Railway (backend application hosting, U.S.-based): runs the Bazu API; processes your requests but does not retain consumer health data beyond the request.
  • OpenAI (AI provider): receives the meal descriptions (text), meal photos (images) and food names needed to identify foods and estimate nutrition. Nothing else is sent with them.
  • Anthropic (AI provider): receives a summary of your recent logging, so it can write the sentences on your score screens. That summary carries your meal names, your score numbers and your nutrient averages. Nothing about glucose goes once the imported readings are deleted (Section 10).
  • Edamam and Open Food Facts (food databases): receive food names and barcode scans from your meal searches. They do not receive any other consumer health data.
  • Sentry (crash and error monitoring): may receive minimal identifiers and technical context when the app crashes or hits an error. We configure Sentry to exclude the contents of meals, check-in answers, weight, any diabetes answer, glucose readings, insulin doses, and every other category in Section 2.

Neither OpenAI nor Anthropic receives your name, email address, account identifier, date of birth, weight, any diabetes answer, energy check-in answers, an individual glucose reading, or an insulin dose. Data sent to either one via API is not used to train their models, per their API terms, and is held by them for no more than 30 days for abuse monitoring.

We do not share consumer health data with any advertising network, data broker, analytics partner, marketing partner, insurer, employer, or any other third party not listed above. Nothing in Section 2 ever reaches an advertising platform, an ad audience or a marketing segment.

6. We Do Not Sell Consumer Health Data

We do not sell consumer health data. We have not sold consumer health data in the preceding twelve (12) months and have no plans to do so.

Washington law forbids selling consumer health data without your signed, written valid authorization (RCW 19.373.050), which is a separate document from any consent or from the Terms. We have never sought one, and we never will. Maryland law bans the sale of sensitive data outright.

We also do not share consumer health data for cross-context behavioral advertising or for any advertising purpose. The limited advertising-identifier sharing with Meta and TikTok described in our Privacy Policy involves no consumer health data.

7. Your Rights

If you are a Washington or Nevada resident, you have the following rights regarding your consumer health data:

  • Right to confirm whether we are collecting, sharing, or selling your consumer health data, and to access the data we have collected.
  • Right to a list of all third parties with whom we have shared or to whom we have sold your consumer health data, along with active contact information for each. Section 5 is that list; on request we will send it with a working contact address for each provider.
  • Right to delete your consumer health data. We will delete it from our active records, from our archives and backups within 90 days, and we will tell every provider listed in Section 5 to delete it too.
  • Right to withdraw consent for our collection or sharing of your consumer health data. Because the Service cannot rate food without your meals, withdrawing consent means closing your account: delete it in the app, or email us and we will delete it for you (Section 8).
  • Right to appeal any denial of a request under this section (see Section 9).
  • Right to non-discrimination for exercising any of the rights above.

8. How to Exercise Your Rights

To exercise any of the rights in Section 7:

  • Delete everything yourself: in the Bazu app, open Settings, then Delete Account. Section 10 says what happens next.
  • Withdraw consent: delete your account in the app, or email us with the subject line “Withdraw consent” and we will delete it for you. Either way, collection stops at once.
  • Everything else: email hello@withbazu.com with the subject line “Consumer Health Data Request.” Include your full name, the email address on your Bazu account, and what you want. If you are submitting on behalf of another person, include evidence of your authorization to act.

Washington residents: we will respond within forty-five (45) days. We may extend this period once by another forty-five (45) days when reasonably necessary, and will notify you of the extension and the reason within the initial 45 days. Nevada residents: we will respond within sixty (60) days, extendable once by thirty (30) days on the same terms.

9. Right to Appeal

If we deny your request, you may appeal that denial by replying to our denial email or by emailing hello@withbazu.com with the subject line “Consumer Health Data Appeal.” Within forty-five (45) days of receiving your appeal, we will inform you in writing of the action we have taken or have decided not to take, along with our reasons.

If we deny your appeal, you may submit a complaint to the Washington State Attorney General at https://www.atg.wa.gov/file-complaint, or to the Nevada Attorney General at https://ag.nv.gov/Complaints/File_Complaint/. Our denial will tell you how.

10. How Long We Keep Consumer Health Data, and How It Is Deleted

Every category in Section 2 is kept while your account is active, and no longer, with one dated exception below.

When you delete your account

Deleting your account starts a 30-day grace period. During it your data is kept but inactive, and logging back in restores the account. When the 30 days end, a scheduled job permanently erases every category in Section 2 in one pass, including meal photos, check-in answers, weight history, the dated diabetes record, and any glucose, insulin or CGM value an earlier app version stored. We then instruct the providers in Section 5 to delete what they hold. Backups are purged within 90 days. No consumer health data survives. What we keep afterwards is not consumer health data: the record that you accepted our terms and policies, and the record of your deletion request, each holding the account's internal identifier and dates and nothing about you or your health (see our Privacy Policy, Section 6).

Readings app versions before 2.3.0 imported from Apple Health

Every imported reading, and every curve and time-in-range figure computed from them, was deleted from every account fourteen days after app version 2.3.0 was released. Each affected account was emailed on release day with the date and the offer of a copy. An app version before 2.3.0 that keeps syncing until it is updated has its readings deleted on the next run of the same deletion. In September 2026 we made one encrypted offline copy of the readings of two accounts as part of removing this integration; no third party has it, it was never sent to any AI model or vendor, and it is destroyed on December 14, 2026.

11. Security

Consumer health data is encrypted in transit and at rest. Access inside Bazu is restricted to the people and systems that need it to operate the Service, and database rules ensure each account can read only its own data. Meal photos are stored privately and opened only through short-lived links issued to your signed-in account. Our Privacy Policy (Section 5) describes our security measures in full.

12. How We Ask for Your Consent

Before we collect any consumer health data, the app asks you to agree to this policy with its own, separate choice. That choice is not part of accepting the Terms of Service, and it is recorded on its own with the version you agreed to and the date. If we ever wanted to collect a new category of consumer health data, or use what we hold for a new purpose, we would tell you first and ask again. You can withdraw your consent at any time as described in Section 8.

13. Residents of Other States

We treat consumer health data the same way for every user, wherever they live. If you live in a state with its own health-data law, the rights in Section 7 are available to you on the same terms, and where that law gives you more, the law controls. In particular:

  • Connecticut: consumer health data is processed only with your opt-in consent, and we do not profile you from it.
  • Maryland: we collect only the consumer health data strictly necessary to provide the Service you asked for, and we never sell it.
  • Vermont, New York and any other state with a health-information privacy law: the same collection limits, the same no-sale rule and the same rights apply.

14. Changes to This Policy

We may update this Consumer Health Data Privacy Policy from time to time. When we make a material change, we will notify you in the app or by email, and we will update the version number and the “Last Updated” date at the top. A change never applies a new purpose to data we already hold without your consent (Section 4).

15. Contact

For any question about this Consumer Health Data Privacy Policy:

Bazu Technologies, LLC

Email: hello@withbazu.com

Website: https://withbazu.com

Version History

  • 3.0, September 2026: Apple Health glucose import, the predicted glucose curves and manual glucose and insulin entry were removed in app version 2.3.0, and every imported reading was deleted fourteen days after that release, with notice. Categories reorganized around food, energy check-ins and weight. Withdrawal by email or account deletion, Nevada timelines and other-state rights added.
  • 2.0, June 2026: first published.

© 2026 Bazu Technologies, LLC. All rights reserved.